Skip to content
Stored XSS Vulnerability in WatchGuard Fireware OS (CVE-2026-13374)

Stored XSS Vulnerability in WatchGuard Fireware OS (CVE-2026-13374)

First seen 12 Aug 2026, 03:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 13, 2026 at 03:04 UTC
  • •CVE-2026-13374 allows Stored XSS in WatchGuard Fireware OS, affecting multiple versions.
  • •This vulnerability is linked to CVE-2025-13937, providing an additional attack vector.
  • •Affected systems include Fireware OS versions 12.4 to 12.12 and 12.5 up to 12.5.18.

A Cross-site Scripting (XSS) vulnerability, identified as CVE-2026-13374, has been discovered in WatchGuard Fireware OS, specifically within the ConnectWise Technology Integration module. This vulnerability allows for Stored XSS attacks, which can lead to unauthorized access and data manipulation. It is an additional attack vector related to CVE-2025-13937. The affected versions include Fireware OS 12.4 through 12.12, 12.5 up to 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 2, 2026, and is currently unmitigated, posing a significant risk to users of the affected software. Security professionals are advised to monitor the situation closely and apply any forthcoming patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2025-12-04
CVE-2025-13937 published
A vulnerability related to WatchGuard Fireware OS was disclosed, establishing a connection to CVE-2026-13374.
nvd.nist.gov
2026-07-02
CVE-2026-13374 published
The Stored XSS vulnerability in WatchGuard Fireware OS was officially published, affecting several versions.
nvd.nist.gov
2026-08-12
NVD updates CVE-2026-13374
The National Vulnerability Database enriched the CVE record for CVE-2026-13374, highlighting its implications.
nvd.nist.gov

More articles in this cluster (2)

Following this threat?

Track CVE-2025-13937 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed